
Auto Subpage Menu Security & Risk Analysis
wordpress.org/plugins/auto-subpage-menuBy default wordpress menu system, wordpress can only automatically add/remove top-level page to/from menus
Is Auto Subpage Menu Safe to Use in 2026?
Generally Safe
Score 85/100Auto Subpage Menu has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "auto-subpage-menu" v1.1.5 reveals a strong security posture with no identified critical vulnerabilities in the analyzed code. The absence of dangerous functions, file operations, external HTTP requests, and the proper use of prepared statements for its single SQL query are all positive indicators. Furthermore, all identified outputs are properly escaped, and there are no taint flows with unsanitized paths, suggesting robust data handling practices within the plugin's current code. The vulnerability history is also clear, with no recorded CVEs, indicating a historically safe plugin.
However, the most significant concern arises from the complete lack of any observed entry points, such as AJAX handlers, REST API routes, shortcodes, or cron events. While this might seem like a strength, it could also indicate that the plugin has no user-facing functionality or is not actively interacting with WordPress in a way that would trigger these entry points. More critically, the absence of any capability checks or nonce checks across any potential entry points (even though none were explicitly found) is a significant oversight. If any entry points were to be introduced or if the analysis missed any subtle interaction points, the lack of these fundamental WordPress security mechanisms would leave the plugin highly vulnerable to privilege escalation or unauthorized actions.
Key Concerns
- No capability checks found
- No nonce checks found
Auto Subpage Menu Security Vulnerabilities
Auto Subpage Menu Code Analysis
SQL Query Safety
Auto Subpage Menu Attack Surface
WordPress Hooks 2
Maintenance & Trust
Auto Subpage Menu Maintenance & Trust
Maintenance Signals
Community Trust
Auto Subpage Menu Alternatives
PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus
capability-manager-enhanced
PublishPress Capabilities is the access control plugin. You can manage user capabilities, permissions, user roles, admin menus and more.
User Admin Simplifier
user-admin-simplifier
Lets any Administrator simplify the WordPress Admin interface, on a per-user basis, by turning specific menu/submenu sections off.
Admin Tools
admin-tools
Admin Tools Helps you to get better admin for your customers. Manage your menus, plugins, Top Bar, updates and more
Ozh' Admin Drop Down Menu
ozh-admin-drop-down-menu
All admin links available in a neat horizontal drop down menu. Saves lots of screen real estate!
Admin Toolbar Menus
admin-toolbar-menus
Seamlessly adds 3 new menu locations to the admin toolbar.
Auto Subpage Menu Developer Profile
6 plugins · 2K total installs
How We Detect Auto Subpage Menu
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.